Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the G
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Inj
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects A
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises use
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores interm
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remot
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and
mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool.
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta
Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe
Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async,
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async,
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execu
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up t
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Objec
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — fu
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when impor
pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra
The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthentic
The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructor
GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18
Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJ
NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an uns
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started